Arbitrary file upload in Tenable Nessus - CVE-2023-6062
Published: November 20, 2023
Vulnerability identifier: #VU83307
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-6062
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of file during file upload. A remote user with administrative privileges can alter Nessus Rules variables and overwrite arbitrary files on the remote host, leading to denial of service.
Affected software
Tenable Nessus
How to mitigate CVE-2023-6062
Install updates from vendor's website.
Tenable Nessus - addressed in versions 10.5.7, 10.6.3